02·Concept·10 min
Domains and DNS
The last lesson started with "the name is resolved to an address". This one opens that step up: what a domain actually is, and how one name finds one app.
Owning a name is a lease
Each ending (.com, .kr, .app) is run by a registry that keeps the master list of names under it. You never deal with the registry directly. You rent a name through a registrar, a company accredited to sell names under that ending, one year at a time. Stop paying and the name expires; after a grace period the registry releases it and anyone can register it.
Nameservers: who answers
When you register a name you also say which nameservers answer questions about it. Those servers hold the name's records. Whoever runs your nameservers decides where your name points.
Records
A record is one line: a host, a type, and a value.
- A: a name to an IPv4 address. AAAA is the same for IPv6.
- CNAME: a name to another name ("www.shop.com is whatever shop-app.host.net is").
- TXT: free text, mostly used to prove you control the name to some service.
- MX: which servers receive email for the name.
The bare name (shop.com, the apex) cannot be a CNAME, because it already carries other records the standard says must stand alone. That is why hosts usually ask for an A record on the apex and a CNAME on www.
Caching and TTL
Resolvers cache every answer for its TTL (time to live, in seconds). Change a record and every resolver that cached the old one keeps serving it until its TTL runs out. That is "propagation": nothing is spreading, old answers are just expiring at different times on different networks.
Proving the name is yours
Before a host serves your app on a name, and before an authority signs an https certificate for it, both want proof that you control the name. The usual proofs are the records themselves: the name already points at the host, or a TXT record holds a token the host gave you. A certificate cannot be issued until the name points at the right place, which is why the padlock shows up a little after the records do.
Where DontCode fits
- Bought on DontCode: DontCode's registrar also runs the nameservers, so the records are written for you. The name is live on your project about a minute after the order clears, with nothing to paste.
- Bought elsewhere: your registrar still runs the nameservers. Manage Domains shows the records to add there (an A record for the apex, a CNAME for a subdomain), then verifies them and issues the certificate.
Names bought on DontCode live on the Domains page in your account menu, billed in credits. Registrars renew about 30 days before expiry, so DontCode emails you 45 days out and charges 35 days out. If a name lapses, DontCode takes it off the project and the app stays up on its free dontcode.cafe address.
Go deeper
Check your understanding
1.Who decides where a domain points?
2.Why do hosts ask for an A record on shop.com but a CNAME on www.shop.com?
3.You changed a record with a TTL of 3600. Some visitors still reach the old server. Why?
4.Why is letting a domain your app used expire a security risk?